Description
A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-05-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a stack‑based buffer overflow in the formSetFirewallRule function, triggered by an oversized firewall_name argument. This vulnerability, identified as CWE-119 and CWE-121, can be abused from a remote host to overwrite the return pointer on the stack, potentially allowing an attacker to execute arbitrary code and compromise the device’s confidentiality, integrity or availability. The CVSS score of 8.7 reflects the high severity of this remote attack.

Affected Systems

The issue exists solely on TRENDnet TEW‑432BRP devices running firmware 3.10B20, a unit that has been out of support since 2009. The vendor has stated it cannot replicate or patch the flaw, meaning the vulnerability remains only on legacy hardware that remains in use.

Risk and Exploitability

A public exploit demonstrates that the attack can be carried out without authentication from a remote host, elevating the risk for any network still hosting this device. Although the EPSS score is not available, the lack of an official fix, the EOL status of the product, and the confirmed remote execution capability make the threat highly likely. The vulnerability is not listed in CISA’s KEV catalog, but the high CVSS combined with the public exploit warrants immediate action to mitigate exposure.

Generated by OpenCVE AI on May 30, 2026 at 16:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether the TEW-432BRP device is still deployed within the network environment.
  • If the device must remain, isolate it by moving it to a dedicated VLAN.
  • If the device must remain, restrict remote management to a single authorized host.
  • If the device must remain, block ports used by the /goform interface.
  • Replace the device with a supported, security‑maintained router or firewall that receives timely updates.

Generated by OpenCVE AI on May 30, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 30 May 2026 15:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Title TRENDnet TEW-432BRP formSetFirewallRule stack-based overflow
First Time appeared Trendnet
Trendnet tew-432brp
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:trendnet:tew-432brp:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-432brp
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trendnet Tew-432brp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-30T14:30:08.664Z

Reserved: 2026-05-29T17:19:21.599Z

Link: CVE-2026-10120

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-30T15:16:15.173

Modified: 2026-05-30T15:16:15.173

Link: CVE-2026-10120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-30T17:00:07Z

Weaknesses